﻿using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Configuration;
using System.Data.SqlClient;

namespace FYPHP
{
    public partial class _Default : System.Web.UI.Page
    {
        SqlConnection conn = new SqlConnection(ConfigurationManager.ConnectionStrings["fyphp"].ConnectionString);
        string x;

        protected void Page_Load(object sender, EventArgs e)
        {
            try
            {
                SqlCommand cmdProduct;
                SqlDataReader dtrProduct;
                conn.Open();

                cmdProduct = new SqlCommand("SELECT * FROM Products ORDER BY p_views DESC", conn);
                dtrProduct = cmdProduct.ExecuteReader();

                String thead = "<table class='thumbs' width='100%' cellpadding='5' cellspacing='5' border='1' bordercolor='#aaa' align='center' style='border-collapse: collapse; text-align: center'>";
                String tbox = "";
                String tfoot = "</tr></table>";

                if (dtrProduct.HasRows)
                {
                    for (int i = 0; i < 2; i++)
                    {
                        for (int j = 0; j < 4; j++)
                        {
                            if (dtrProduct.Read())
                            {
                                tbox += "<td width='170px' valign='top'><a href='/ProductDetails.aspx?id=" + dtrProduct["p_id"] + "'><img src='/uploads/products/" + dtrProduct["p_picture"] + "' alt='' height='160px' width='160px' /></a><br />"
                                        + "<a href='/ProductDetails.aspx?id=" + dtrProduct["p_id"] + "'>" + dtrProduct["p_name"] + "</a></td>";
                            }
                        }
                        tbox += "</tr><tr>";
                    }
                }
                Label1.Text = thead + tbox + tfoot;

                dtrProduct.Close();
                conn.Close();
            }
            catch (SqlException ex)
            {
                MessageBox(ex.Message);
            }
        }

        private void MessageBox(string msg)
        {
            Label lbl = new Label();
            lbl.Text = "<script language='javascript'>" + Environment.NewLine + "window.alert('" + msg + "')</script>";
            Page.Controls.Add(lbl);
        }
    }
}
